PT-2026-64578 · Linux+1 · Linux Kernel+1

CVE-2026-64357

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the XFS file system where the xfs exchmaps estimate overhead() function incorrectly performs a UINT MAX check. The function adds bmbt and rmapbt overhead to a local resblks variable but validates the reservation using the original req->resblks value instead of the updated total. This computed value is subsequently stored in req->resblks and passed to the xfs trans alloc() function, which expects an unsigned integer for the block reservation argument.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64357
OPENSUSE-SU-2026:11476-1
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu